The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.
2007-03-31T01:19:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.1 (HIGH)
AV:N/AC:H/Au:S/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | broadcom | brightstor_arcserve_backup | 9.01 | Yes |
Application | broadcom | brightstor_arcserve_backup | 11.1 | Yes |
Application | broadcom | brightstor_arcserve_backup | 11.5 | Yes |
Application | broadcom | brightstor_arcserve_backup | 11.5 | Yes |
Application | broadcom | brightstor_arcserve_backup | 11.5 | Yes |
Application | ca | brightstor_arcserve_backup | 11 | Yes |